GoogleKmsCryptoKey class final
Factory wrapper for google_kms_crypto_key.
A CryptoKey represents a logical key that can be used for cryptographic
operations.
~> Note: CryptoKeys cannot be deleted from Google Cloud Platform. Destroying a Terraform-managed CryptoKey will remove it from state and delete all CryptoKeyVersions, rendering the key unusable, but will not delete the resource from the project. When Terraform destroys these keys, any data previously encrypted with these keys will be irrecoverable. For this reason, it is strongly recommended that you add lifecycle hooks to the resource to prevent accidental destruction.
Example:
final ring = GoogleKmsKeyRing(
'main',
name: TfArg.literal('main-ring'),
location: TfArg.literal('asia-northeast1'),
);
final cryptoKey = GoogleKmsCryptoKey(
'payments',
name: TfArg.literal('payments'),
keyRing: ring.ref,
purpose: KmsKeyPurpose.encryptDecrypt,
// Must be > 86400s (1 day). `TfArg.duration` converts the
// Duration into the `"{seconds}s"` form Terraform expects.
rotationPeriod: TfArg.duration(const Duration(days: 90)),
versionTemplate: KmsCryptoKeyVersionTemplate(
algorithm: .literal('GOOGLE_SYMMETRIC_ENCRYPTION'),
protectionLevel: KmsProtectionLevel.software,
),
);
Note: CryptoKeys cannot be deleted from GCP. Destroying a
Terraform-managed CryptoKey removes it from state and renders all
CryptoKeyVersions unusable but does not delete the resource from the
project. Consider attaching lifecycle { prevent_destroy = true } for
production keys.
Constructors
-
GoogleKmsCryptoKey(String localName, {required TfArg<
String> name, required RefTo<GoogleKmsKeyRing> keyRing, KmsKeyPurpose? purpose, TfArg<String> ? rotationPeriod, TfArg<Map< ? labels, TfArg<String, String> >bool> ? skipInitialVersionCreation, TfArg<String> ? destroyScheduledDuration, TfArg<bool> ? importOnly, TfArg<String> ? cryptoKeyBackend, KmsCryptoKeyVersionTemplate? versionTemplate, LifecycleOptions? lifecycle, List<TfAddressed> ? dependsOn, StackProvider? provider, TfTimeouts? timeouts})
Properties
-
argMap
→ Map<
String, TfArg?> -
Argument-name → TfArg map. Keys are snake_case (Terraform JSON name).
Synth emits these keys directly; the factory is responsible for the
camelCase → snake_case translation at construction time.
finalinherited
-
cryptoKeyBackend
→ TfRef<
String> -
Reference to
crypto_key_backendattribute.no setter - defaultProvider → String
-
The provider name a block without provider uses: by default the
prefix of terraformType (
googleforgoogle_pubsub_topic).no setterinherited -
deletionPolicy
→ TfRef<
String> -
Reference to
deletion_policyattribute.no setter -
dependsOn
→ List<
TfAddressed> ? -
Optional
depends_on = [...]: the resources, data sources and module calls this block waits for, e.g.dependsOn: [api, ...apiDeps]. Terraform takes whole blocks only, so an entry is never an attribute.finalinherited -
destroyScheduledDuration
→ TfRef<
String> -
Reference to
destroy_scheduled_durationattribute.no setter -
effectiveLabels
→ TfRef<
Map< String, String> > -
Reference to
effective_labelsattribute.no setter - hashCode → int
-
The hash code for this object.
no setterinherited
-
id
→ TfRef<
String> -
Reference to
idattribute.no setter -
importOnly
→ TfRef<
bool> -
Reference to
import_onlyattribute.no setter -
keyRing
→ TfRef<
String> -
Reference to
key_ringattribute.no setter - kind → ResourceKind
-
Always
ResourceKind.resource. Overridden byData.no setterinherited -
labels
→ TfRef<
Map< String, String> > -
Reference to
labelsattribute.no setter - lifecycle → LifecycleOptions?
-
Optional
lifecycle { ... }block.finalinherited - localName → String
-
User-supplied local name within a Stack.
finalinherited
-
name
→ TfRef<
String> -
Reference to
nameattribute.no setter -
primary
→ TfRef<
List< Map< >String, Object?> > -
Reference to
primaryattribute.no setter - provider → StackProvider?
-
Optional Terraform
providermeta-argument: the provider configuration this block uses, e.g. the aliasedGoogleProvider(alias: 'eu')the Stack registered withaddProvider.finalinherited -
purpose
→ TfRef<
String> -
Reference to
purposeattribute.no setter -
ref
→ RefTo<
GoogleKmsCryptoKey> -
A reference to this resource, for arguments typed
RefTo<GoogleKmsCryptoKey>.no setter -
rotationPeriod
→ TfRef<
String> -
Reference to
rotation_periodattribute.no setter - runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
-
sensitiveFields
→ Set<
String> -
Field names that are
@Sensitiveper the IR-derived per-resource constant. Curated factories override with a baked-instatic const Set<String>(file-private in v0.5+).no setteroverride -
skipInitialVersionCreation
→ TfRef<
bool> -
Reference to
skip_initial_version_creationattribute.no setter - supportsDeletionProtection → bool
-
Capability flag: true when this resource's underlying Terraform
schema has a
deletion_protectionboolean attribute that the synth-time devMode flow can flip tofalse. Defaults to false; the codegen emitter overrides this totruefor wrappers whose schema includes the attribute.no setterinherited -
terraformLabels
→ TfRef<
Map< String, String> > -
Reference to
terraform_labelsattribute.no setter - terraformType → String
-
Terraform resource type, e.g.
google_pubsub_topic.finalinherited - tfAddress → String
-
Terraform address
<terraformType>.<localName>, e.g.google_pubsub_topic.orders.no setterinherited - timeouts → TfTimeouts?
-
Optional
timeouts { ... }block: how long Terraform waits for each operation. Provider-neutral like lifecycle — synth copies the duration strings verbatim, andterraform validatedecides whether this resource's schema declares the operations set here.finalinherited
Methods
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toString(
) → String -
A string representation of this object.
inherited
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited